Combine review and analysis around the CWE-639 trust boundary
MITRE identifies automated static analysis as applicable detection approaches. Use them to find lookups where a request-controlled object key selects data and verify the authorization decision checks ownership or policy for the resolved object, not merely key validity. Require a reproducible source-to-sink or policy-to-enforcement trace, record coverage gaps, and confirm suspected findings dynamically where safe; no single scanner can establish complete coverage for this weakness.
CWE-639: detection methods and operational guidance — MITRE CWE